Vendor
OpenBao vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 13 vulnerabilities in OpenBao: 3 in the last 7 days and 7 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-63132, was published on 23 September 2026. 1 technology has a page of its own.
- Last 7 days
- 3
- Last 90 days
- 7
- Critical, all time
- 2
- Exploited in the wild
- 0
About OpenBao
An open-source community project providing a software suite for managing secrets, certificates, and sensitive data.
OpenBao technologies
- OpenBao13
Latest OpenBao vulnerabilities
- CVE-2026-63132: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path…criticalCVSS 4EPSS 0.5%
- CVE-2026-63131: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could…mediumCVSS 6EPSS 0.4%
- CVE-2026-71543: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies…highCVSS 4EPSS 0.4%
- CVE-2026-55776: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with…mediumCVSS 6.5EPSS 0.6%
- CVE-2026-55775: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities on…lowCVSS 2.3EPSS 0.5%
- CVE-2026-55774: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to…lowCVSS 2.1EPSS 0.6%
- CVE-2026-55770: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC…mediumCVSS 6.8EPSS 0.5%
- CVE-2026-46405: OpenBao Kerberos auth method orphaned token accumulationmediumCVSS 5.3EPSS 0.6%
- CVE-2026-46358: OpenBao sensitive information disclosure in audit logsmediumCVSS 4EPSS 0.2%
- CVE-2026-45808: OpenBao authorization bypass in sys/revoke and sys/renew endpointshighCVSS 7.1
- CVE-2026-42186: OpenBao improper data removal during namespace deletion retryhighCVSS 7.5EPSS 0.0%
- CVE-2026-33758: OpenBao reflected XSS in OIDC authentication callbackmediumCVSS 6.1EPSS 0.4%
- CVE-2026-33757: OpenBao session fixation via OIDC direct callback modecriticalCVSS 9.6EPSS 0.6%
Most severe OpenBao vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-33757: OpenBao session fixation via OIDC direct callback modecriticalCVSS 9.6EPSS 0.6%
- CVE-2026-63132: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path…criticalCVSS 4EPSS 0.5%
- CVE-2026-42186: OpenBao improper data removal during namespace deletion retryhighCVSS 7.5EPSS 0.0%
- CVE-2026-45808: OpenBao authorization bypass in sys/revoke and sys/renew endpointshighCVSS 7.1
- CVE-2026-71543: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, templated ACL, PKI, and SSH policies…highCVSS 4EPSS 0.4%
- CVE-2026-55770: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC…mediumCVSS 6.8EPSS 0.5%
- CVE-2026-55776: OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with…mediumCVSS 6.5EPSS 0.6%
- CVE-2026-33758: OpenBao reflected XSS in OIDC authentication callbackmediumCVSS 6.1EPSS 0.4%
- CVE-2026-63131: OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could…mediumCVSS 6EPSS 0.4%
- CVE-2026-46405: OpenBao Kerberos auth method orphaned token accumulationmediumCVSS 5.3EPSS 0.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 4 | 0 | |
| 21 Sep 2026 | 3 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/openbao.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "OpenBao vulnerabilities", https://junglewise.ai/threats/vendors/openbao, 26 September 2026.